If you're a practicing auditor, a QA reviewer, or a CAP III student in Nepal, NSA 2024 is no longer a "coming soon" topic — mandatory compliance is already in effect. This guide walks through what actually changed from the earlier Nepal Standards on Auditing, why it changed, and what it means in practice for engagement letters, working papers, report wording, and exam preparation.
What NSA 2024 is and why ICAN adopted it
Nepal Standards on Auditing 2024 (NSA 2024) is the current auditing framework pronounced by the Auditing Standards Board of Nepal (AuSB), following the decision of ICAN's 324th Council meeting on 29 April 2024. The standards were developed based on the 2021 Handbook of International Quality Control, Auditing, Review, Other Assurance, and Related Service Pronouncements issued by the International Auditing and Assurance Standards Board (IAASB) — meaning Nepal's auditing standards now track a considerably more recent edition of the global framework than the previous version did. The adoption reflects ICAN's ongoing commitment, as a member body of IFAC, to keep Nepal's audit quality and reporting requirements aligned with current international norms, particularly around quality management and risk-based audit approaches.
Effective date — mandatory compliance from mid-2025
NSA 2024 followed a phased rollout that auditors should have on their radar for any historical engagement review. Voluntary compliance began on 16 July 2024 (1 Shrawan 2081), giving firms roughly a year to transition their methodology, templates, and training before mandatory compliance took effect on 16 July 2025 (1 Shrawan 2082). This means any audit of a period beginning on or after that date must be conducted, documented, and reported under NSA 2024 — not the earlier standard. Firms that have continued using legacy NSA 2018 templates for engagements falling after this cutoff are technically out of compliance and should prioritize an immediate methodology update.
Key structural changes from the earlier Nepal Standards on Auditing
The most significant structural shift is at the quality framework level: the previous Nepal Standard on Quality Control (NSQC 1) is superseded by the newer Nepal Standards on Quality Management framework (NSQM 1 and NSQM 2), which moves audit firms from a largely compliance-driven quality control model toward a proactive, risk-based quality management system that firms must actively design, operate, and monitor rather than simply follow. Beyond quality management, NSA 2024 carries forward the full suite of standards for historical financial information audits and other assurance engagements, but with expanded guidance on risk identification and response, reflecting the more granular risk-assessment requirements introduced in the IAASB's 2021 Handbook compared to the 2016 edition that underpinned the earlier Nepali standards.
Scenario-based audit reporting — what examiners and QA reviewers are checking
Under NSA 2024, auditor's report requirements move further toward scenario-specific wording rather than a single generic template. QA reviewers and ICAN examiners are increasingly testing whether a candidate or firm can correctly identify which report variant applies to a given fact pattern — unmodified versus modified opinions, the specific circumstances requiring an Emphasis of Matter versus a Key Audit Matters (KAM) paragraph, and how to word a report when there are multiple, interacting issues (for example, a scope limitation combined with a material uncertainty related to going concern). Reviewers are also paying closer attention to whether firms can demonstrate — through documented risk assessments and response procedures — that the reported opinion is actually supported by evidence gathered under the newer risk-based standards, rather than simply carried forward from a prior year's template.
Practical impact on engagement letters, working papers, and report wording
For firms actually running engagements, three documents typically need the earliest attention. Engagement letters should be revised to reference NSA 2024 (and NSQM 1/2 where applicable) rather than the superseded 2018 standards, and should reflect any updated responsibilities language flowing from the newer standards. Working paper templates need to capture the more granular risk assessment and response documentation NSA 2024 expects — a generic risk checklist inherited from the old NSQC 1 era is unlikely to satisfy a QA reviewer testing against the new framework. Finally, auditor's report templates should be updated to reflect current wording conventions for Key Audit Matters, Other Information, and going concern paragraphs, matching the structure now expected under the 2021 IAASB Handbook basis. Firms that update only the cover letter while leaving working paper methodology unchanged are the most common finding in early NSA 2024 QA reviews.
What CAP III students should specifically revise for exams
For CAP III students, the safest assumption is that any audit-related paper now expects answers grounded in NSA 2024, not the earlier standard. Priority revision areas include: the shift from NSQC 1 to NSQM 1/2 and what that means for a firm's quality management system versus quality control system; scenario-based report modification questions (practice matching fact patterns to the correct opinion type and paragraph structure); and the updated risk assessment and response framework, since exam scenarios increasingly test whether a candidate can trace a specific audit procedure back to a specific identified risk, rather than listing generic procedures. Students preparing from older study material should specifically cross-check any auditor's report format or quality control terminology against the current AuSB-published NSA 2024 text, since older notes may still reference NSQC 1 language that no longer applies.
How small and mid-size audit firms should update their audit manuals
Smaller firms often carry the highest compliance risk here simply because a full manual rewrite competes with client work for partner time. A practical, sequenced approach: first, replace the quality control section of the firm manual with a genuine quality management system addressing NSQM 1 (for the firm generally) and NSQM 2 (for engagement quality reviews on qualifying engagements), including a documented risk assessment of the firm's own quality objectives — this is the single highest-priority item, since it is a firm-level requirement rather than an engagement-by-engagement one. Second, update standard working paper templates and checklists to reflect the expanded risk-assessment documentation NSA 2024 expects. Third, refresh auditor's report templates for every report variant the firm commonly issues. Firms without in-house technical resource to manage this update should consider commissioning a one-time methodology review from a specialist rather than attempting a full DIY rewrite under time pressure.
FAQ: Does NSA 2024 apply to all audits or only listed entities?
NSA 2024 applies broadly to audits of historical financial information across engagement types in Nepal — it is not restricted to listed companies. The applicability question that firms should instead focus on is engagement complexity and public interest: certain enhanced requirements, particularly around engagement quality reviews under NSQM 2, apply specifically to entities that meet the criteria for a "public interest" or otherwise higher-risk classification, meaning listed companies, banks, and similarly regulated entities carry additional obligations beyond the baseline NSA 2024 requirements that apply to smaller private-entity audits. Firms should confirm the specific applicability tier for each client against the AuSB's published implementation guidance rather than assuming a one-size-fits-all approach.
Disclaimer
This article is a general summary of publicly available information on NSA 2024 and is intended for informational purposes only. It does not constitute professional or regulatory advice. Auditors, firms, and students should refer directly to the official NSA 2024 text published by the Auditing Standards Board of Nepal (AuSB) and ICAN's official notices for authoritative guidance, and should consult a qualified professional for advice specific to any engagement.
Related reading: Watch this space for our companion guides on Nepal Standards on Quality Management (NSQM 1 & 2) in practice, and on AML/CFT compliance obligations for Nepali audit and accounting firms — both currently in progress.
Discussion